from pathlib import Path import pytest from app.common.security import is_allowed_chat, is_owner from app.repository.security import safe_repository_path def test_owner_is_checked_by_numeric_id() -> None: assert is_owner(42, 42) assert not is_owner(41, 42) assert not is_owner(None, 42) def test_chat_allowlist_accepts_only_project_group_and_owner_dm() -> None: assert is_allowed_chat(-100, "supergroup", -100, 42) assert is_allowed_chat(42, "private", -100, 42) assert not is_allowed_chat(77, "private", -100, 42) assert not is_allowed_chat(-101, "group", -100, 42) def test_repository_path_rejects_traversal_and_secret_files(tmp_path: Path) -> None: (tmp_path / "src").mkdir() assert safe_repository_path(tmp_path, "src/main.py") == tmp_path / "src/main.py" with pytest.raises(ValueError): safe_repository_path(tmp_path, "../outside") with pytest.raises(ValueError): safe_repository_path(tmp_path, ".env") with pytest.raises(ValueError): safe_repository_path(tmp_path, "key.pem")